They use the Startup folder in order to obtain persistence in the system. There are two different Startup folders. If the folder C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup is used, the malware will be executed when the user [Username] logs in. On th...